nuclei-templates/misconfiguration/aem/aem-default-get-servlet.yaml

81 lines
2.8 KiB
YAML

id: aem-default-get-servlet
info:
author: DhiyaneshDk
name: AEM DefaultGetServlet
severity: low
reference: https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=43
tags: aem
requests:
- method: GET
path:
- '{{BaseURL}}/.json'
- '{{BaseURL}}/.1.json'
- '{{BaseURL}}/....4.2.1....json'
- '{{BaseURL}}/.json?FNZ.css'
- '{{BaseURL}}/.json?FNZ.ico'
- '{{BaseURL}}/.json?FNZ.html'
- '{{BaseURL}}/.json/FNZ.css'
- '{{BaseURL}}/.json/FNZ.html'
- '{{BaseURL}}/.json/FNZ.png'
- '{{BaseURL}}/.json/FNZ.ico'
- '{{BaseURL}}/.children.1.json'
- '{{BaseURL}}/.children....4.2.1....json'
- '{{BaseURL}}/.children.json?FNZ.css'
- '{{BaseURL}}/.children.json?FNZ.ico'
- '{{BaseURL}}/.children.json?FNZ.html'
- '{{BaseURL}}/.children.json/FNZ.css'
- '{{BaseURL}}/.children.json/FNZ.html'
- '{{BaseURL}}/.children.json/FNZ.png'
- '{{BaseURL}}/.children.json/FNZ.ico'
- '{{BaseURL}}/etc.json'
- '{{BaseURL}}/etc.1.json'
- '{{BaseURL}}/etc....4.2.1....json'
- '{{BaseURL}}/etc.json?FNZ.css'
- '{{BaseURL}}/etc.json?FNZ.ico'
- '{{BaseURL}}/etc.json?FNZ.html'
- '{{BaseURL}}/etc.json/FNZ.css'
- '{{BaseURL}}/etc.json/FNZ.html'
- '{{BaseURL}}/etc.json/FNZ.ico'
- '{{BaseURL}}/etc.children.json'
- '{{BaseURL}}/etc.children.1.json'
- '{{BaseURL}}/etc.children....4.2.1....json'
- '{{BaseURL}}/etc.children.json?FNZ.css'
- '{{BaseURL}}/etc.children.json?FNZ.ico'
- '{{BaseURL}}/etc.children.json?FNZ.html'
- '{{BaseURL}}/etc.children.json/FNZ.css'
- '{{BaseURL}}/etc.children.json/FNZ.html'
- '{{BaseURL}}/etc.children.json/FNZ.png'
- '{{BaseURL}}/etc.children.json/FNZ.ico'
- '{{BaseURL}}///etc.json'
- '{{BaseURL}}///etc.1.json'
- '{{BaseURL}}///etc....4.2.1....json'
- '{{BaseURL}}///etc.json?FNZ.css'
- '{{BaseURL}}///etc.json?FNZ.ico'
- '{{BaseURL}}///etc.json/FNZ.html'
- '{{BaseURL}}///etc.json/FNZ.png'
- '{{BaseURL}}///etc.json/FNZ.ico'
- '{{BaseURL}}///etc.children.json'
- '{{BaseURL}}///etc.children.1.json'
- '{{BaseURL}}///etc.children....4.2.1....json'
- '{{BaseURL}}///etc.children.json?FNZ.css'
- '{{BaseURL}}///etc.children.json?FNZ.ico'
- '{{BaseURL}}///etc.children.json?FNZ.html'
- '{{BaseURL}}///etc.children.json/FNZ.css'
- '{{BaseURL}}///etc.children.json/FNZ.html'
- '{{BaseURL}}///etc.children.json/FNZ.png'
- '{{BaseURL}}///etc.children.json/FNZ.ico'
stop-at-first-match: true
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- 'jcr:createdBy'
condition: and